Vulnerability GHSA-7h5p-637f-jfr7

High Risk
HIGH RISK
CVSS Score: 8.6
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
3 months ago
June 19, 2026 at 09:15 PM UTC
StarCitizenWiki Extension Embed Video: Stored XSS via unsanitized class passed to template
3.0.0 - 4.0.0
3.0.0 - 4.0.0

Summary

StarCitizenWiki Extension Embed Video: Stored XSS via unsanitized class passed to template

Details

Summary

The user supplied class value is fed directly into the sprintf call that creates HTML. You can add a quote to escape the class and then inject arbitrary html/javascript to the final output.

Details

The template here adds a figure with a class that is substituted in. This value is provided to sprintf here, an unescaped version of the class supplied by the user.

$template = <<<HTML
    <figure class="%s" data-service="%s" %s %s>
        <div class="embedvideo-wrapper" %s>%s%s%s</div>%s
    </figure>
HTML;

PoC

Note the double quote immediately following the single quote to escape the class attribute in the template:

<youtube class='" onmouseover="alert(document.domain)' id="dQw4w9WgXcQ">dQw4w9WgXcQ</youtube>

Impact

Arbitrary HTML can be inserted into the DOM by any user on any page, allowing for JavaScript to be executed.

Timeline

Published
3 months ago
June 19, 2026 at 09:15 PM UTC
Fixed (4.1.0)
3 months ago
June 19, 2026 at 06:27 PM UTC
Last Modified
18 days ago
September 10, 2026 at 03:50 AM UTC